DATA DISCOVERY

Find the personal data hiding in your files.

Find the personal data hiding in your files.

Enterprise-grade discovery of sensitive data — scanned documents included — without the enterprise price, the deployment project, or your files ever leaving the building.

Enterprise-grade discovery of sensitive data — scanned documents included — without the enterprise price, the deployment project, or your files ever leaving the building.

Runs entirely on your machine · No account needed · Signed installer with published checksum

THE QUESTION

The question every UK organisation must be able to answer

The question every UK organisation must be able to answer

“What personal data do you hold, and where is it?”

“What personal data do you hold, and where is it?”

Sooner or later this question arrives in writing — on a client’s due-diligence questionnaire, a cyber-insurance renewal, or a letter from the ICO. And it’s an uncomfortable one, because for most firms the honest answer is we’re not entirely sure. Not through carelessness. Twenty years of ordinary work simply leaves data in places nobody can see into any more.

“Doing an information audit or data-mapping exercise can help you find out what personal data your organisation holds and where it is… Knowing what information you have, where it is, and what you do with it makes it much easier for you to comply with other aspects of the UK GDPR.”

— INFORMATION COMMISSIONER’S OFFICE

Two things have made the question sharper lately:

Subject access requests

Someone writes in asking what you hold on them, and the clock starts. Right of access is already the single largest category of data-protection complaint to the ICO, and under the Data (Use and Access) Act 2025 you must be able to show a reasonable and proportionate search. Not perfection — the law doesn’t demand you find every byte. Proof that you looked properly. A documented scan is exactly that proof.

What a breach actually exposes

In April 2025 the ICO fined a law firm £60,000 after attackers stole 32 GB of its data. Not a bank, not a FTSE company — a regional practice. And what was stolen wasn’t a database. It was ordinary files: court bundles, PDFs, Word documents, photographs relating to clients. For most firms, that’s what the risk really looks like. Not a server room — a file store.

THE MARKET

The data that matters is hiding in your scans

The data that matters is hiding in your scans

Think about how a client actually joins a firm. Someone photographs a passport. Scans a bank letter. Saves a signed form out of an email. Those files land in a folder called Scans, an old matter file, an archive drive — and they never leave. Multiply that by every client you’ve ever taken on, and you’re holding the most sensitive collection of documents your business owns, sitting exactly where no search box can reach it.

Because a scanned passport is a picture. Text search cannot see inside it. A tool that only reads the text of your files will report those folders clean — and be wrong precisely where the risk is highest.

Reading images takes optical character recognition (OCR), and OCR is where discovery tools quietly part company. We went and checked, properly. This is what buying that capability actually looks like in August 2026:

Enterprise data-security platforms

VARONIS · BIGID · SPIRION · NETWRIX DATA CLASSIFICATION

Capable — and quote-only, with no self-serve purchase path. Independent contract analyses put typical entry deals in five figures per year, deployed via collector servers, endpoint agent fleets or a dedicated SQL Server: a project with a sales cycle, not a purchase.

Microsoft Purview

IF YOU RUN MICROSOFT 365

A capable platform built for a different job. Endpoint classification needs a paid add-on per user. OCR is optional and metered at $1 per 1,000 items — every page of a PDF counts as an item — and needs your Global Admin to set up Azure pay-as-you-go billing first. By default it reads only images added after you switch it on, and endpoint OCR works by sending images from your devices to Microsoft’s cloud — Microsoft’s own documentation: “the devices start sending messages to the cloud for scanning.” Scanning an on-premises file share needs a Windows Server plus SQL Server scanner deployment.

Budget tools with published prices

The affordable discovery tools scan file-server text. Their published documentation lists no OCR of images or scanned PDFs — so the scanned IDs and bank letters, the highest-risk files in the building, come back invisible.

Put yourself in the position of a 20-person firm with a folder of scanned client IDs. Until now there was no realistic way to answer the regulator’s question: the tools that could read those files were built and priced for enterprises, and the tools you could afford couldn’t read them.

That gap is why PCRiskPro exists.

That gap is why PCRiskPro exists.

WHAT’S DIFFERENT

What PCRiskPro does differently

Five deliberate choices.

1

It reads scanned documents as standard

OCR is built in — not an add-on, not metered, not something your IT provider has to wire up first. PCRiskPro reads scanned PDFs, images and photographs of documents, including the machine-readable zone of scanned passports, validated with its check digits — so the foreign passports in your right-to-work records are found too, not just UK ones. And this isn’t a lab feature: in field testing, PCRiskPro worked overnight through a 13,000-file professional archive — more than 7,000 of them scanned PDFs — and finished without a single error.

Password-protected and unreadable files aren’t skipped silently, either. They’re named in your results, so you know exactly which files still need a human eye.

2

Nothing leaves the building

PCRiskPro runs entirely on the machine you install it on. Your files are read locally, findings are stored locally, reports are written locally. There’s no cloud back-end, no upload, no account — so when a client asks where their passport scan went, the answer is: nowhere. It never left your machine. There is no copy of your clients’ documents on our servers, because there are no servers. Contrast the mainstream route, where endpoint OCR means images travel to a cloud service to be read.

3

It audits what you already hold

Most data-protection tooling polices data in motion — it watches what happens to new files from the day it’s configured. That’s useful, but it doesn’t touch the question that keeps people up at night: what’s already there. PCRiskPro audits data at rest — the fifteen years of scanned onboarding sitting in your archive right now. Point it at a folder, a drive, or a synced SharePoint/OneDrive library and it inspects what’s actually in there — including, on Enterprise licences, cloud-only files it can download and scan on demand. When a subject access request arrives, a scan plus a search for the person’s name is a documented, defensible answer instead of an anxious afternoon.

4

It shows its working

Ask any auditor: a report is worth exactly as much as what it admits. Every PCRiskPro scan tells you what was inspected — and what wasn’t. The coverage summary reads “122 of 123 files inspected” and names the file that couldn’t be read, rather than staying quiet about it. Exports include a per-file audit manifest: every file, its outcome, and how deeply it was examined. A clean result says “we looked and found nothing” — never just a blank screen. And results are deterministic: the same files produce the same findings on a different machine. This is a report you can hand to an auditor, a client, or your own insurer without caveats you didn’t write.

5

It’s built for UK data, and tuned for precision

More than 40 built-in detection patterns, written for the data UK organisations actually hold: National Insurance numbers, NHS numbers (checksum-validated), UK passports, Biometric Residence Permits and Home Office references, driving licences, sort codes and account numbers (validated against their labels, so a spreadsheet of six-digit amounts doesn’t light up as “200 exposed bank details”), payment cards with Luhn checksums, and plaintext credentials — API keys, passwords, private keys — that have no business sitting in a shared folder. A default UK scan runs 35 active detectors; US and EU locale patterns ship disabled, deliberately, because on UK estates they produce false positives — and nothing erodes trust in a security tool faster than a page of false alarms. Findings are mapped to the frameworks they touch — UK GDPR, PCI-DSS, Cyber Essentials — as a readiness indicator for your own review.

IF YOU ALREADY RUN MICROSOFT 365

Run both — they answer different questions

This page isn’t here to talk you out of Purview — it’s good at what it’s for. Purview is a policy engine: it polices what happens to data across Microsoft 365 from the day your administrator configures it. PCRiskPro answers the other question: what’s already there — on the laptops, the mapped drives, the synced libraries and the archive folders, in formats and scans accumulated over years. Plenty of firms should run both: Purview watching the front door, PCRiskPro auditing the building. And if you’re on Business Premium, it’s worth knowing that endpoint classification isn’t in your base licence at all — it’s a paid add-on, before OCR metering.

HONEST SCOPE

What PCRiskPro is not

Most products save this part for the small print. We’d rather you knew before you download — a wasted evaluation costs you an afternoon and us your trust:

It’s not continuous monitoring. PCRiskPro runs point-in-time scans when you choose to run them. It’s an audit tool, not a surveillance agent.

It doesn’t block, quarantine or delete anything. It finds, reports, and lets you track remediation. It never modifies your files — scanning is read-only by design.

It’s a per-device Windows application. It scans what the machine it runs on can see — local drives, mapped drives, synced cloud folders. No servers to stand up, no agents to deploy; equally, no central console.

It scans files, not systems. Mailboxes, databases and SaaS applications are out of scope; cloud document libraries are in scope through their synced folders.

It’s UK-first. US and EU patterns exist in the engine but ship disabled, deliberately.

And one more, which is really the point: when PCRiskPro can’t read something, it tells you. A tool whose job is honesty about your data should start by being honest about itself.

TRY IT

Prove it on your own files — in minutes

We could tell you it works. We’d rather show you — on your files, not our demo data:

1

The installer is signed by PCRiskpro Limited, and its SHA-256 checksum is published on the page so you can verify it before running.

2

Scan the folder you’re curious about

You know the one. No account, no sales call, and nothing leaves your machine.

3

Read the results

The Free Edition shows your first 20 findings in full detail. And if your files come back clean, it will say so plainly — which is an answer worth having too.

Licences run from £95 a year for a single machine to business licences with cloud-scope scanning — every price is published in full at pcriskpro.com/pricing. No quotes, no sales cycle, no minimum seats. If the product doesn’t earn the licence, don’t buy it.

SOURCES

Market facts checked 19 August 2026; Microsoft licensing and pricing change frequently — verify current figures against the sources below.

1. ICO — Documentation: what is documentation?

2. ICO Annual Report 2024/25; Personnel Today — SAR complaints rise

3. ICO — The Data (Use and Access) Act 2025: what it means for organisations

4. ICO enforcement — DPP Law Ltd, 14 April 2025

5. Vendor purchase pages verified individually, August 2026: Varonis, BigID, Spirion, Netwrix and others publish no prices (“contact sales”).

6. Independent contract analyses (Vendr; ITQlick; VendorBenchmark), 2025–2026 — third-party estimates, not vendor price lists.

7. Microsoft Learn — OCR in Microsoft Purview; pay-as-you-go pricing; Information Protection scanner prerequisites

8. ManageEngine DataSecurity Plus data discovery documentation and Lepide data classification materials, which list no image or scanned-document content among discoverable types (August 2026).

PCRiskPro finds and evidences sensitive data; it does not by itself make an organisation compliant with any framework, and no detection technology finds everything — which is why every PCRiskPro report states its own coverage.